<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: OpenShift Log Forwarding to Splunk in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/OpenShift-Log-Forwarding-to-Splunk/m-p/635696#M52101</link>
    <description>&lt;P&gt;Yes, I tried to execute below curl command&lt;/P&gt;&lt;P&gt;curl &lt;A href="http://splunk-hec.amosirelanddev.amosonline.io:8000/en-GB/services/collector/event" target="_blank"&gt;http://splunk-hec.amosirelanddev.amosonline.io:8000/en-GB/services/collector/event&lt;/A&gt; -d '{"event": "hello world"}'&lt;/P&gt;&lt;P&gt;curl &lt;A href="http://splunk-hec.amosirelanddev.amosonline.io:8000/services/collector/event" target="_blank"&gt;http://splunk-hec.amosirelanddev.amosonline.io:8000/services/collector/event&lt;/A&gt; -d '{"event": "hello world"}'&lt;/P&gt;&lt;P&gt;but getting 303 Page not found! Error.&lt;/P&gt;</description>
    <pubDate>Thu, 23 Mar 2023 12:14:55 GMT</pubDate>
    <dc:creator>Suchita1</dc:creator>
    <dc:date>2023-03-23T12:14:55Z</dc:date>
    <item>
      <title>OpenShift Log Forwarding to Splunk?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/OpenShift-Log-Forwarding-to-Splunk/m-p/635672#M52096</link>
      <description>&lt;P&gt;We are using OpenShift 4.11.27 and now looking for OpenShift Log Forwarding to Splunk.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did below changes at OpenShift end to configure splunk:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Installed cluster-logging and elasticsearch-operator into OpenShift.
&lt;P&gt;$ oc get csv -n openshift-logging&lt;/P&gt;
&lt;P&gt;NAME&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DISPLAY&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VERSION&amp;nbsp;&amp;nbsp; REPLACES&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; PHASE&lt;/P&gt;
&lt;P&gt;cluster-logging.v5.6.3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Red Hat OpenShift Logging&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5.6.3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; cluster-logging.v5.6.2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Succeeded&lt;/P&gt;
&lt;P&gt;elasticsearch-operator.v5.6.3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; OpenShift Elasticsearch Operator&amp;nbsp;&amp;nbsp; 5.6.3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; elasticsearch-operator.v5.6.2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Succeeded&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Created secret vector-splunk-secret using below command:
&lt;P&gt;$ oc -n openshift-logging create secret generic vector-splunk-secret --from-literal hecToken=&amp;lt;HEC_Token&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;We have create clusterlogforwarders as below:
&lt;P&gt;---&lt;/P&gt;
&lt;P&gt;&amp;nbsp; apiVersion: "logging.openshift.io/v1"&lt;/P&gt;
&lt;P&gt;&amp;nbsp; kind: "ClusterLogForwarder"&lt;/P&gt;
&lt;P&gt;&amp;nbsp; metadata:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; name: "instance"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; namespace: "openshift-logging"&lt;/P&gt;
&lt;P&gt;&amp;nbsp; spec:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; outputs:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - name: splunk-receiver&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; secret:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; name: vector-splunk-secret&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; type: splunk&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; url: &lt;A href="http://splunk-hec.amosirelanddev.amosonline.io:8000" target="_blank" rel="noopener"&gt;http://splunk-hec.amosirelanddev.amosonline.io:8000&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; pipelines:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - inputRefs:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - application&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - infrastructure&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; name:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; outputRefs:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - splunk-receiver&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Updated cluster logging operator as it was using fluentd so replaced fluentd with vector:
&lt;P&gt;$ oc edit ClusterLogging instance -n openshift-logging&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Splunk Setup changes:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Splunk installation on VM done with below steps:
&lt;OL&gt;
&lt;LI&gt;wget &lt;A href="https://download.splunk.com/products/splunk/releases/8.0.4/linux/splunk-8.0.4-767223ac207f-linux-2.6-x86_64.rpm" target="_blank" rel="noopener"&gt;https://download.splunk.com/products/splunk/releases/8.0.4/linux/splunk-8.0.4-767223ac207f-linux-2.6-x86_64.rpm&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;sudo rpm -ivh splunk-8.0.4-767223ac207f-linux-2.6-x86_64.rpm&lt;/LI&gt;
&lt;LI&gt;Two indexes created. Create new index as per below list.&amp;nbsp;&lt;STRONG&gt;&lt;STRONG&gt;Settings&amp;nbsp;&amp;gt;&amp;nbsp;&lt;STRONG&gt;Indexes&amp;nbsp;&amp;gt;&amp;nbsp;&lt;STRONG&gt;New Index&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/STRONG&gt;
&lt;OL&gt;
&lt;LI&gt;openshift (events)&lt;/LI&gt;
&lt;LI&gt;openshift-matrix (matix)
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Enabling HEC token - Enable HEC (HTTP Event Collector),&amp;nbsp;Settings&amp;nbsp;&amp;gt;&amp;nbsp;Data Inputs &amp;gt; HTTP Event Collector&amp;nbsp;&amp;gt;&amp;nbsp;Global Settings&amp;nbsp;&amp;gt;&amp;nbsp;Default Index&amp;nbsp;as “Default” &amp;gt;&amp;nbsp;Save&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;STRONG&gt;Create HEC token - Create new HEC token,&amp;nbsp;Settings&amp;nbsp;&amp;gt;&amp;nbsp;Data inputs&amp;nbsp;&amp;gt;&amp;nbsp;HTTP Event Collector&amp;nbsp;&amp;gt;&amp;nbsp;New Token&amp;nbsp;&amp;gt;&amp;nbsp;Name&amp;nbsp;as “openshift” &amp;gt;&amp;nbsp;Next&amp;nbsp;(Input Settings, add allowed indexes like below” &amp;gt;&amp;nbsp;Review&amp;nbsp;&amp;gt;&amp;nbsp;Submit. Note the&amp;nbsp;Token Value, we going to use this for next step.&lt;/STRONG&gt;&lt;/STRONG&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;We are trying to search from New Search “index= openshift” but not getting any result.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class=""&gt;&lt;BR /&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Where we can see the logs on Splunk dashboard or if we are missing something then please let us know.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Suchita Deshmukh&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Tue, 28 Mar 2023 14:13:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/OpenShift-Log-Forwarding-to-Splunk/m-p/635672#M52096</guid>
      <dc:creator>Suchita1</dc:creator>
      <dc:date>2023-03-28T14:13:02Z</dc:date>
    </item>
    <item>
      <title>Re: OpenShift Log Forwarding to Splunk</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/OpenShift-Log-Forwarding-to-Splunk/m-p/635690#M52098</link>
      <description>&lt;P&gt;There could be many reasons for events not reaching Splunk. From network configurations to permissions from the cluster side or even port configuration for HEC. Have you tried sending a simple curl message using HEC token to the Splunk&amp;nbsp; from the cluster instance to see if its reaching?&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2023 12:06:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/OpenShift-Log-Forwarding-to-Splunk/m-p/635690#M52098</guid>
      <dc:creator>Gr0und_Z3r0</dc:creator>
      <dc:date>2023-03-23T12:06:33Z</dc:date>
    </item>
    <item>
      <title>Re: OpenShift Log Forwarding to Splunk</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/OpenShift-Log-Forwarding-to-Splunk/m-p/635696#M52101</link>
      <description>&lt;P&gt;Yes, I tried to execute below curl command&lt;/P&gt;&lt;P&gt;curl &lt;A href="http://splunk-hec.amosirelanddev.amosonline.io:8000/en-GB/services/collector/event" target="_blank"&gt;http://splunk-hec.amosirelanddev.amosonline.io:8000/en-GB/services/collector/event&lt;/A&gt; -d '{"event": "hello world"}'&lt;/P&gt;&lt;P&gt;curl &lt;A href="http://splunk-hec.amosirelanddev.amosonline.io:8000/services/collector/event" target="_blank"&gt;http://splunk-hec.amosirelanddev.amosonline.io:8000/services/collector/event&lt;/A&gt; -d '{"event": "hello world"}'&lt;/P&gt;&lt;P&gt;but getting 303 Page not found! Error.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2023 12:14:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/OpenShift-Log-Forwarding-to-Splunk/m-p/635696#M52101</guid>
      <dc:creator>Suchita1</dc:creator>
      <dc:date>2023-03-23T12:14:55Z</dc:date>
    </item>
    <item>
      <title>Re: OpenShift Log Forwarding to Splunk</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/OpenShift-Log-Forwarding-to-Splunk/m-p/635707#M52103</link>
      <description>&lt;P&gt;Check the port configured for HEC, it should be port 8088. You are hitting the web console on port 8000.&lt;BR /&gt;&lt;BR /&gt;Some default ports..&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;8000 Web (default for clients to the Splunk Search page)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;8089 Management/Rest API &amp;amp; Distributed Search (default)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;9997 Indexing Receiver( for forwarders to the Splunk indexer)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;8181 Search replication&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;8080 Index replication&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;8191 KV store/replication&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;8088 http Event Collector&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;8065 Splunk App Server&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;514 Legacy syslog input(UDP/TCP)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;1433 DB Connector(to fetch data from databases to Splunk)&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2023 12:58:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/OpenShift-Log-Forwarding-to-Splunk/m-p/635707#M52103</guid>
      <dc:creator>Gr0und_Z3r0</dc:creator>
      <dc:date>2023-03-23T12:58:32Z</dc:date>
    </item>
    <item>
      <title>Re: OpenShift Log Forwarding to Splunk</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/OpenShift-Log-Forwarding-to-Splunk/m-p/635907#M52120</link>
      <description>&lt;P&gt;$ sudo netstat -lnpt&lt;BR /&gt;Active Internet connections (only servers)&lt;BR /&gt;Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name&lt;BR /&gt;tcp 0 0 0.0.0.0:9997 0.0.0.0:* LISTEN 114868/splunkd&lt;BR /&gt;tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN 991/sshd&lt;BR /&gt;tcp 0 0 0.0.0.0:8088 0.0.0.0:* LISTEN 114868/splunkd&lt;BR /&gt;tcp 0 0 0.0.0.0:8089 0.0.0.0:* LISTEN 114868/splunkd&lt;BR /&gt;tcp 0 0 0.0.0.0:8191 0.0.0.0:* LISTEN 114889/mongod&lt;BR /&gt;tcp 0 0 0.0.0.0:8000 0.0.0.0:* LISTEN 114868/splunkd&lt;BR /&gt;tcp 0 0 127.0.0.1:8065 0.0.0.0:* LISTEN 114963/python3.7&lt;BR /&gt;tcp6 0 0 :::22 :::* LISTEN 991/sshd&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have updated port from 8000 to 8088&lt;/P&gt;&lt;P&gt;$ curl -v &lt;A href="https://splunk-hec.amosirelanddev.amosonline.io:8088/services/collector" target="_blank"&gt;https://splunk-hec.amosirelanddev.amosonline.io:8088/services/collector&lt;/A&gt;&lt;BR /&gt;* Trying 176.34.143.107...&lt;BR /&gt;* TCP_NODELAY set&lt;BR /&gt;* Connected to splunk-hec.amosirelanddev.amosonline.io (176.34.143.107) port 8088 (#0)&lt;BR /&gt;* ALPN, offering h2&lt;BR /&gt;* ALPN, offering http/1.1&lt;BR /&gt;* successfully set certificate verify locations:&lt;BR /&gt;* CAfile: /etc/pki/tls/certs/ca-bundle.crt&lt;BR /&gt;CApath: none&lt;BR /&gt;* TLSv1.3 (OUT), TLS handshake, Client hello (1):&lt;BR /&gt;* TLSv1.3 (IN), TLS handshake, Server hello (2):&lt;BR /&gt;* TLSv1.2 (IN), TLS handshake, Certificate (11):&lt;BR /&gt;* TLSv1.2 (OUT), TLS alert, unknown CA (560):&lt;BR /&gt;* SSL certificate problem: self signed certificate in certificate chain&lt;BR /&gt;* Closing connection 0&lt;BR /&gt;curl: (60) SSL certificate problem: self signed certificate in certificate chain&lt;BR /&gt;More details here: &lt;A href="https://curl.haxx.se/docs/sslcerts.html" target="_blank"&gt;https://curl.haxx.se/docs/sslcerts.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;curl failed to verify the legitimacy of the server and therefore could not&lt;BR /&gt;establish a secure connection to it. To learn more about this situation and&lt;BR /&gt;how to fix it, please visit the web page mentioned above.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It seams certs are not valid. Could you send me procedure how to update certs for splunk.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2023 11:52:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/OpenShift-Log-Forwarding-to-Splunk/m-p/635907#M52120</guid>
      <dc:creator>Suchita1</dc:creator>
      <dc:date>2023-03-24T11:52:08Z</dc:date>
    </item>
    <item>
      <title>Re: OpenShift Log Forwarding to Splunk</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/OpenShift-Log-Forwarding-to-Splunk/m-p/636267#M52164</link>
      <description>&lt;P&gt;you can follow this document from splunk about securing your infrastructure.&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.4/Security/AboutsecuringyourSplunkconfigurationwithSSL" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.4/Security/AboutsecuringyourSplunkconfigurationwithSSL&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.4/Security/RenewExistingCerts" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.4/Security/RenewExistingCerts&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;If the reply helps, karma vote would be appreciated!&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 09:00:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/OpenShift-Log-Forwarding-to-Splunk/m-p/636267#M52164</guid>
      <dc:creator>Gr0und_Z3r0</dc:creator>
      <dc:date>2023-03-28T09:00:09Z</dc:date>
    </item>
    <item>
      <title>Re: OpenShift Log Forwarding to Splunk</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/OpenShift-Log-Forwarding-to-Splunk/m-p/638754#M52230</link>
      <description>&lt;P&gt;Please provide steps to apply ssl certs for splunk..&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2023 05:01:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/OpenShift-Log-Forwarding-to-Splunk/m-p/638754#M52230</guid>
      <dc:creator>Suchita1</dc:creator>
      <dc:date>2023-04-05T05:01:13Z</dc:date>
    </item>
    <item>
      <title>Re: OpenShift Log Forwarding to Splunk</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/OpenShift-Log-Forwarding-to-Splunk/m-p/638781#M52234</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/255051"&gt;@Suchita1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can refer the below documentation for SSL certs, based on your system architecture configure them accordingly.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.4/Security/AboutsecuringyourSplunkconfigurationwithSSL" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.4/Security/AboutsecuringyourSplunkconfigurationwithSSL&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Note: Select the documentation based on the Splunk version you are using. You can see it in the top right corner of product and version.&lt;BR /&gt;&lt;BR /&gt;~ If the reply helps, a karma upvote would be appreciated.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Apr 2023 08:03:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/OpenShift-Log-Forwarding-to-Splunk/m-p/638781#M52234</guid>
      <dc:creator>Gr0und_Z3r0</dc:creator>
      <dc:date>2023-04-05T08:03:55Z</dc:date>
    </item>
    <item>
      <title>Re: OpenShift Log Forwarding to Splunk</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/OpenShift-Log-Forwarding-to-Splunk/m-p/660807#M54374</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;We installed the splunk with version 8.0.4 from scratch and created the clusterlogging and clusterlogforwarder instance with vector pointing to splunk vm.&lt;/P&gt;&lt;P&gt;Still we are unable to see the logs in the dashboard even sample logs are also not visible in the dashboard.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Guru Sairam&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2023 04:27:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/OpenShift-Log-Forwarding-to-Splunk/m-p/660807#M54374</guid>
      <dc:creator>GuruSairam</dc:creator>
      <dc:date>2023-10-16T04:27:03Z</dc:date>
    </item>
  </channel>
</rss>

